Skip to main content

Vendor/product archive

lfedge / eve CVEs

Beta · best-effort

3 CVEs tagged to lfedge / eve0 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-43637

Published Sep 21, 2023

Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This iss…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43634

Published Sep 21, 2023

When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected b…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43633

Published Sep 21, 2023

On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the existing configuration on the d…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1